Zapier for WordPress Security & Risk Analysis

wordpress.org/plugins/zapier

Zapier saves you time on tedious tasks by moving info between WordPress and your other favorite apps, so you can focus on your most important work.

50K active installs v1.5.3 PHP 7.4+ WP 5.5+ Updated Jul 24, 2025
automationdataflowintegrationworkflowzapier
98
A · Safe
CVEs total2
Unpatched0
Last CVEJun 19, 2025
Download
Safety Verdict

Is Zapier for WordPress Safe to Use in 2026?

Generally Safe

Score 98/100

Zapier for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jun 19, 2025Updated 8mo ago
Risk Assessment

The static analysis of the "zapier" plugin v1.5.3 reveals a generally strong security posture with excellent adherence to WordPress development best practices. The absence of any detected dangerous functions, raw SQL queries, unescaped output, or file operations is highly commendable. Furthermore, the plugin exhibits proper nonce and capability checks, indicating that its internal operations are well-protected against common WordPress vulnerabilities. The zero-day attack surface and zero taint flows with unsanitized paths further bolster confidence in its code quality. However, the history of two medium-severity CVEs, specifically related to Missing Authorization and SSRF, warrants attention. While currently unpatched, this history suggests a past vulnerability that could potentially be exploited if not addressed in newer versions or if this specific version is maintained. The plugin's reliance on external HTTP requests also introduces potential risks if those endpoints are compromised or if data transmitted is not adequately secured.

Key Concerns

  • Past Medium CVEs (Missing Auth, SSRF)
  • External HTTP requests (potential for compromise)
Vulnerabilities
2

Zapier for WordPress Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-50010medium · 4.3Missing Authorization

Zapier for WordPress <= 1.5.2 - Missing Authorization

Jun 19, 2025 Patched in 1.5.3 (37d)
CVE-2024-13411medium · 6.4Server-Side Request Forgery (SSRF)

Zapier for WordPress <= 1.5.1 - Authenticated (Subscriber+) Blind Server-Side Request Forgery via updated_user Function

Mar 25, 2025 Patched in 1.5.2 (1d)
Code Analysis
Analyzed Mar 16, 2026

Zapier for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
2
Capability Checks
6
File Operations
0
External Requests
4
Bundled Libraries
0
Attack Surface

Zapier for WordPress Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Zapier for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJul 24, 2025
PHP min version7.4
Downloads677K

Community Trust

Rating44/100
Number of ratings72
Active installs50K
Developer Profile

Zapier for WordPress Developer Profile

Zapier

2 plugins · 50K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
19 days
View full developer profile
Detection Fingerprints

How We Detect Zapier for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zapier/assets/css/styles.css/wp-content/plugins/zapier/assets/js/zapier.js/wp-content/plugins/zapier/assets/js/settings.js
Script Paths
/wp-content/plugins/zapier/assets/js/zapier.js/wp-content/plugins/zapier/assets/js/settings.js
Version Parameters
zapier/assets/css/styles.css?ver=zapier/assets/js/zapier.js?ver=zapier/assets/js/settings.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-nonce
JS Globals
Zapier.Settings
REST Endpoints
/wp-json/zapier/v1/token/wp-json/zapier/v1/roles/wp-json/zapier/v1/webhook/wp-json/zapier/v1/(?P<type>[a-zA-Z0-9_-]+)/supports
FAQ

Frequently Asked Questions about Zapier for WordPress